Wallet Tracer
Free, open-source blockchain forensics tools. Trace your stolen funds. Help law enforcement. Recover what you can.
See It In Action
Full investigation panel — trace, export, and file evidence-grade reports
The same network map, full-featured on your phone
This Is Real
This tool was built from real investigation work. Cases have been filed with law enforcement. Evidence has been documented on the blockchain and preserved for authorities.
You're not alone. Justice, though it takes time, is being pursued through proper channels.
Proven on Real Cases
Firelight — Active Investigation (2026)
The theft that started this project: 8,306.686379 stXRP drained via phishing contract on Flare, June 16, 2026. Full custody was traced hop-by-hop — victim wallet → phishing contract → attacker redemption wallet → a three-way structuring split → a single consolidation hub → confirmed deposits at both OKX and Bybit hot wallets. The consolidation hub alone is one node in a mapped network of 49,892 addresses, including 7,551 wallets classified as likely victims of the same operation. Every hop is a citable, independently-verifiable transaction hash on Flarescan.
Filed: FBI IC3, FinCEN SAR, OKX, Bybit, Gate.io, Kraken, Flare Foundation.
Bitfinex 2016 Hack — Independent Verification
To validate the tool's Bitcoin engine, the 2016 Bitfinex hack was independently retraced from the hacker's own recipient address, with no reference to the DOJ's investigative work. The tool followed 567.2576 BTC from that address to the same government seizure address the DOJ named in its 2022 announcement — a match to the publicly reported ~567.5 BTC transfer, within the precision expected from proportional UTXO attribution. The seizure address terminus totaled ≈94,685 BTC in the tool's export against DOJ's reported 94,636–94,643 BTC recovered. The trace mapped 9,243 nodes and 9,448 edges, entirely from public blockchain data.
Nothing about this case was fed to the tool — it reconstructed the same DOJ-published outcome from scratch.
Real Exhibits
This is what a generated exhibit actually looks like — pulled straight from a live investigation, victim wallet on the left, exchange endpoints on the right, every hop documented and clickable back to its own transaction.
A Word to Victims
"If you're here because you lost funds to a phishing scam, theft, or fraud—you're not alone. This tool exists because someone experienced exactly what you're going through. Use it. Share it. And know that justice, though it takes time, is being pursued."
📄 Read the full letterHow It Works
Trace the Amount, Not the Guess
Start from the attacker's side: enter the phishing contract or attacker wallet and auto-trace its network. Anchor the trace to a specific token and amount, and it follows only the transfers matching that value — hop by hop through relays and consolidation hubs to the exchange — instead of guessing which transaction looks big enough.
Behavioral Classification
Automatically classifies wallets by how they behave: consolidation hubs, pass-through relays, routers, likely victims, and exchange endpoints. See the shape of an operation instead of a hairball of addresses — and get warned when a pattern is only a lead, not a verdict.
Contract Intel — No Source Required
Most scam contracts are unverified, so explorers show you nothing but hex. This reads the raw bytecode anyway: hardcoded drain destinations, admin and fee-collector wallets, the contract's real function set, and whether it's a CREATE2 factory — meaning the operator sits one level up. It also calls the contract's own getters and scans storage to recover payout addresses set at runtime, the ones never baked into the code.
Template Fingerprinting
Every contract gets a bytecode fingerprint. Identical code means an identical fingerprint — so a fleet of scam contracts collapses into "one toolkit, many deployments." Load a deployer's full contract list and see at a glance which ones share an owner.
Evidence-Grade Exports
Chain-of-custody path documents, flagged-only or full-network exhibits with network diagrams, victim census CSV, exchange-deposit-feeder CSV, and XRPL destination-tag CSV. Formatted to attach to an IC3 complaint, a FinCEN SAR, or an exchange compliance request. Autosaves as you work, with full backup and restore.
XRP Ledger — Destination Tags
Full XRPL support, not just EVM chains. And XRPL gives you something no EVM chain does: when funds are deposited to an exchange, the transaction carries a destination tag — the exchange's own identifier for the account being credited. On Ethereum you have to ask an exchange who owns a deposit address. Here that identifier is public on-ledger. Tags are read from every trace, drawn directly on the network map, and exported to CSV for compliance requests.
Bitcoin — UTXO Custody Tracing
Bitcoin doesn't work like an account-based chain, so it gets its own engine: legacy (1...), P2SH (3...), bech32 (bc1q...), and taproot (bc1p...) addresses, read via public explorers with no API key required. Change outputs are detected and excluded from custody chains. Multi-input, multi-output transactions are apportioned by proportional attribution — exact for simple splits, a documented approximation for complex consolidations — so a stolen-coin trail doesn't silently inherit unrelated funds. Volume guards keep large exchange-hub transactions from freezing the graph on mobile.
Independently verified against the 2016 Bitfinex hack — see the case study below.
100% Private
Everything runs in your browser. No data sent to servers. No registration required. Your investigation stays yours.
Fast & Free
Single wallets scan in 30-60 seconds, phishing networks in about 5 minutes, full multi-chain traces in about 20 minutes. MIT licensed. Open source. Free forever.
Multi-Chain
Three chain families in one tool. Nine EVM chains — Flare, Songbird, Ethereum, Base, Polygon, Gnosis Chain, Optimism, Arbitrum One, and BNB Smart Chain — plus the XRP Ledger, account-based with its own address format and no smart contracts, plus Bitcoin, a UTXO chain with its own custody model entirely. Contract lookups probe every EVM chain automatically, so a contract is found wherever it actually lives. Built by someone who traced their own stolen stXRP.
More chains added as the tool grows.
AI Analysis — Bring Your Own Key
Optional, and built the same way as everything else here: nothing touches a Wallet-Tracer server, because there isn't one. Add your own Anthropic API key in Settings and every AI call goes directly from your browser to Anthropic — the same no-account, runs-in-your-browser model as the rest of the tool, just extended to AI-assisted analysis.
Evidence-Cited, Not a Verdict
Ask for a pattern read on any wallet and the model returns a structured, cited suggestion — specific evidence points, a confidence tier, and a mandatory alternate explanation. A response with fewer than two cited data points is rejected automatically, before you ever see it. It synthesizes your own case notes and confirmed registries into that read — a wallet you've already tagged "Coinbase Hot Wallet 89" is treated as established fact, not re-guessed from scratch.
Human Review Gate
AI output never overwrites a classification. It sits in its own field until you click Confirm or Reject — and you can run a second opinion on a wallet you've already classified, in case you suspect an earlier call was wrong. If the model's independent read conflicts with your existing classification, it says so explicitly and cites why, instead of silently agreeing or silently overriding you.
The Math Is Never the AI's
When a wallet's exposure to confirmed scam infrastructure is high enough to be worth documenting for regulatory or law-enforcement referral, that percentage is computed directly by the app — across every counterparty, not just a handful — so the number can never be a model estimate or a rounding error. The AI's only job is deciding whether the hard number clears the threshold, and writing up why, with the same "not a verdict" discipline as everything else.
Costs Pennies, Not a Subscription
You're billed directly by Anthropic for your own usage — there's no markup, no Wallet-Tracer fee layered on top. A full investigation, start to finish, typically runs a few dollars in API usage. No subscription, no per-seat license, no data-sharing agreement to read first.
Get Started
Enter Address or Contract Phishing contract, attacker wallet, or an unverified contract to dissect
Auto-Trace Network Tool maps the full fund flow
Log Victim Details Wallet, amount stolen, theft date
Export & File Report for law enforcement, FBI/IC3, or FinCEN